VYPR
Medium severity5.4NVD Advisory· Published Jun 19, 2024· Updated Apr 15, 2026

CVE-2023-39310

CVE-2023-39310

Description

Missing Authorization vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Fusion Builder plugin for WordPress versions up to 3.11.1 have a missing authorization check allowing authenticated attackers to perform unauthorized actions.

Vulnerability

Description CVE-2023-39310 is a missing authorization vulnerability in the ThemeFusion Fusion Builder plugin for WordPress, affecting versions from n/a through 3.11.1 [1]. The plugin fails to properly verify user capabilities before granting access to certain functions, leading to a broken access control issue [1].

Exploitation

An authenticated attacker with low privileges can exploit this flaw by sending crafted requests to the affected endpoint, bypassing authorization checks [1]. No special network position or additional authentication is required beyond a valid WordPress user account [1]. The vulnerability is being used in mass-exploit campaigns targeting thousands of websites [1].

Impact

Successful exploitation allows an attacker to perform actions normally reserved for higher-privileged users, such as modifying site content or settings, depending on the misconfigured function [1]. The CVSS v3 base score is 5.4 (Medium), with a vector indicating low attack complexity and low privileges required [1].

Mitigation

The vulnerability has been patched in version 3.11.2 of Fusion Builder [1]. Users are strongly advised to update immediately. For those unable to update, applying a web application firewall rule or seeking hosting provider assistance can provide temporary protection [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.